CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103889

CRITICALCVSS 9.8NVD feed

Published 10 October 2026 · tracked since 10 October 2026

Description

The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-103889 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103889

CRITICALCVSS 9.8NVD feed

Published 10 October 2026 · tracked since 10 October 2026

Description

The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]